What Is the OpenAI Agents API in 2026?
The Agents API is OpenAI's managed way to run an agent, released in public beta on 10 September 2026. OpenAI describes it as giving "your application access to the Codex harness through an OpenAI-managed API". OpenAI runs the sessions, orchestration, context compaction and recovery; your application supplies the tools and chooses where the agent executes. On 29 September 2026 OpenAI added computer use, so an agent can now work inside an OpenAI-hosted browser.
For a marketing or operations lead the useful translation is this. Until now, building an agent meant building the loop that keeps it going: remembering what it did, recovering when it failed, summarising history when the context filled up. The Agents API takes that loop off your hands. You describe the agent, give it a task, and follow its progress through events or webhooks.
| Attribute | What OpenAI documents in 2026 | Why it matters to a business team |
|---|---|---|
| Status | Public beta since 10 September 2026; SDK calls sit under client.beta.agents | Beta interfaces can change. Do not build a client deliverable that assumes they will not. |
| Who runs the loop | OpenAI runs a managed Codex harness | Lower build effort than writing your own agent loop. |
| Where work executes | OpenAI-hosted sandbox, self-hosted sandbox, or no sandbox | A self-hosted sandbox keeps execution on infrastructure you control. |
| State | Durable sessions with saved configuration, turns and items | An agent can pick up yesterday's task without you replaying the history. |
| Computer use | Added 29 September 2026; runs a browser in an OpenAI-hosted environment | The agent can operate websites through their interface. |
| Pricing | Model usage at the selected model's API rates; hosted sandboxes at standard container rates | There is no separate Agents API fee, but the sandbox meter runs too. |
How Is the Agents API Different From the Agents SDK and the Responses API?
The difference is who runs the agent loop. OpenAI's own comparison puts the Agents API at "Low" integration effort, because OpenAI runs the managed harness and saves progress. The Agents SDK runs inside your application at "Medium" effort and gives you control over deployment, storage and approvals. The Responses API is "High" effort: you call models directly and build the agent yourself.
| Agents API | Agents SDK | Responses API | |
|---|---|---|---|
| OpenAI's stated use | Long-running tasks where OpenAI manages the agent and saves its progress | Building agents with custom tools and workflows in your application | Calling models directly or building an agent from scratch |
| Where the agent runs | OpenAI runs a managed Codex harness | Inside your application | Your application, with optional hosted orchestration |
| Integration effort | Low | Medium | High |
| Execution environment | OpenAI hosted sandbox, self-hosted sandbox, or no sandbox | Your runtime and sandbox provider integrations | Your own execution environment |
OpenAI lists what the managed harness provides: running commands and code in a sandbox, applying skills and instructions, connecting to external data through tools or MCP, steering the agent while it works, summarising previous work to manage the context window, delegating subtasks to subagents, and resuming a session where it left off. Its example applications include an incident response agent, a Slack bot, a read-only SQL data analyst and a document reviewer.
How Does Computer Use Work in the Agents API in 2026?
You enable it with two settings: add { "type": "computer_use" } to the agent's tools, and set the environment to openai_hosted with the desktop enabled. The browser then runs in an OpenAI-hosted environment, and the agent decides what to do next from what it sees on screen. OpenAI frames the uses as testing a website, collecting information, or using an application through its interface.
// From OpenAI's computer use guide: the two settings that enable browser access
agent.tools: [{ "type": "computer_use" }]
environment.type: "openai_hosted"
environment.desktop.enabled: true
Browser activity appears in session output as computer_use_call items, each with a status of in_progress, completed, failed or incomplete. Screenshots are excluded from API output by default; you can turn them on with include_screenshots, and OpenAI warns they "can contain sensitive page or account data" and should be kept out of logs.
Why Do the Approval Rules Matter More Than the Capability?
Because they decide what the agent can do without a person, and the documentation is precise about the limits. The browser "requires the user's approval before accessing each new website origin, including public websites", and enabling network access does not approve those requests. That is a stronger default than most teams would set themselves.
The sentence to read twice is OpenAI's own heading: "Origin approval does not enforce confirmation before individual actions." Approving a website lets the agent act on that website. If your application must guarantee confirmation before purchases, destructive changes or other consequential actions, OpenAI's guidance is to "restrict the hosted browser to resources that cannot perform them, or use a browser runtime you control". It adds that asking for confirmation through a function tool "relies on the agent calling that function", and that website content should be treated as untrusted.
Approving an origin is approving everything the agent might do there. If a site in scope has a "buy", "delete" or "send" button, the safe architecture is to keep that capability away from the agent entirely, not to ask the agent to check in first. OpenAI says this plainly; most agent demos do not.
How sign-in works
Your application handles sign-in, so credentials never pass through the conversation. Submitted sign-in values "stay outside the agent's model input and are omitted from authentication response items in session history". Three limits are documented:
- Only the main agent can request browser authentication; subagents cannot.
- Supported methods are email addresses, passwords and verification codes, "but not passkeys or QR-code sign-in". Sites that require those cannot complete sign-in through this flow.
- Authentication requests expire after five minutes, and a
202response confirms the submission was accepted, not that sign-in succeeded.
What Does It Cost to Run an Agent in 2026?
OpenAI documents three meters. Model usage is billed at the selected model's API rates, OpenAI tools at their standard rates, and OpenAI-hosted sandboxes at standard container rates. The pricing page lists containers at "1 GB $0.03, 4 GB $0.12, 16 GB $0.48, 64 GB $1.92 per 20-minute session per container", with web search at 10 US dollars per 1,000 calls plus search content tokens at model rates.
The model choice dominates. Running the same agent on GPT-6 Luna at 0.10 US dollars per million input tokens is a very different budget from running it on GPT-6 Astra at 10 US dollars. OpenAI's own example sessions use gpt-6-astra; that is a demonstration choice, not a requirement.
How Should Marketing and Operations Teams Use the Agents API in 2026?
Treat it as the build option when you need an agent embedded in your own product or workflow, rather than a person working in ChatGPT. For a team that only wants a capable assistant, OpenAI dots and ChatGPT Work are the no-build routes. The Agents API is for when the agent is part of something you ship or run for clients.
| Workflow | Fit in 2026 | Control to set |
|---|---|---|
| Reading public competitor pages into a weekly brief | Strong. Read-only browsing of public origins. | Approve only the origins in scope. |
| QA of your own landing pages and forms | Strong. OpenAI names website testing as a use. | Point it at staging, not production. |
| Answering internal questions from a warehouse | Good. OpenAI's data analyst example uses read-only SQL. | Read-only credentials, always. |
| Logging into a client's ad account to change budgets | Poor without a controlled runtime. | Origin approval does not confirm individual actions. |
| Anything behind passkey or QR login | Not supported by the sign-in flow. | Use an API integration instead. |
What Are the Common Mistakes With the Agents API in 2026?
- Treating origin approval as action approval. OpenAI says explicitly that it is not.
- Relying on the agent to ask before acting. A confirmation function only works if the agent calls it.
- Keeping your application key inside the sandbox. OpenAI's security guidance is that agent-generated code can read the environment, so keep the application key outside it.
- Logging screenshots. They can contain sensitive account data.
- Assuming closing the stream stops the task. OpenAI notes it does not; cancel the turn.
- Building client deliverables on a beta without a fallback. The Agents API is public beta.
- Forgetting the sandbox meter. Container time is billed separately from model tokens.
Key Takeaways for 2026
- The Agents API entered public beta on 10 September 2026 and gives you OpenAI's managed Codex harness through an API.
- Computer use was added on 29 September 2026, running a browser in an OpenAI-hosted environment.
- Every new website origin needs user approval, including public sites, but that approval does not confirm individual actions.
- Sign-in supports email, passwords and verification codes, not passkeys or QR codes, and only the main agent can request it.
- You pay model rates, tool rates and container rates. There is no separate Agents API fee.
- For most marketing teams, dots or ChatGPT Work are the no-build route; the Agents API is for agents inside your own product or client workflow.
Distk helps growth teams across India and internationally decide where an agent belongs in a workflow, which origins and actions it should never touch, and which model tier keeps it affordable to run every day. If you are scoping an agent build in 2026, that boundary-setting is where we start.
Sources
- OpenAI developer changelog, entries for 10 and 29 September 2026.
- OpenAI, Agents guide (runtime comparison).
- OpenAI, Agents API overview.
- OpenAI, Agents API computer use.
- OpenAI, Agents API environment security.
- OpenAI API pricing.